Apple Resolves iCloud+ Privacy Flaw That Exposed Hidden User Email Addresses
A long-standing vulnerability in the Hide My Email service exposed real user identities through spam bounce-backs.
Apple has deployed a software patch to fix a significant vulnerability in its Hide My Email service, a core privacy feature of the iCloud+ subscription. The flaw reportedly allowed third parties to bypass the service’s anonymity protections and view the actual email addresses of users.
The vulnerability, which Apple reportedly addressed on July 3, functioned by exploiting the way email servers handle rejected messages. When a sender sent an email to a dummy address that was subsequently flagged as spam, the resulting bounce-back notification could inadvertently reveal the recipient’s true identity. This technical oversight undermined the primary purpose of the tool, which is to provide users with unique, random email addresses to prevent tracking and data harvesting by marketers and malicious actors.
Hide My Email was originally introduced in 2021 as part of Apple’s broader “Sign in with Apple” initiative. The feature was designed to give users granular control over their digital footprint, allowing them to delete or deactivate specific dummy addresses if they began receiving unwanted solicitations. By integrating this into the paid iCloud+ tier, Apple positioned privacy as a premium service, a move that has now drawn legal scrutiny following the discovery of the leak.
The timeline of the fix suggests a lengthy delay between the initial report and the final resolution. Tyler Murphy, the co-founder of EasyOptOuts, first alerted Apple to the security gap in June 2025. Despite several attempts by the company to rectify the issue over the following year, Murphy found that the vulnerability persisted, eventually leading him to share his findings with 404 Media.
While the software patch is now active, security experts warn that the damage may already be done for long-term users. Murphy noted that because mail transfer logs are frequently archived by third-party servers, any real email addresses exposed via bounce-backs prior to July 7, 2026, could remain stored in external databases. This permanent record means that users who relied on the feature for anonymity over the past year may still find their primary addresses linked to their dummy accounts in leaked or sold datasets.
Apple’s handling of the situation has triggered a proposed class-action lawsuit. The legal challenge, as reported by PCMag, alleges that Apple engaged in deceptive conduct by charging for a privacy feature that failed to perform its central function. The plaintiffs are seeking the recovery of subscription fees for iCloud+ users, arguing that the company was aware of the defect long before the public fix was implemented.
This incident adds to a growing conversation regarding the reliability of “privacy-first” marketing in the tech industry. Apple has historically used its commitment to user privacy as a competitive advantage against rivals like Google and Meta, often highlighting its hardware and software integration as a safeguard against data exploitation. However, technical vulnerabilities like the Hide My Email leak demonstrate the ongoing difficulty of maintaining total anonymity within the complex global email infrastructure.







